๐ฎ๐น
Inartis
2026-05-30 07:04:10
(4 days ago)
64.89.160.19 - - [30/May/2026:09:04:08 +0200] "GET /.env.example HTTP/1.1" 403 541 "-" "Mozilla/5.0 ...
show more
64.89.160.19 - - [30/May/2026:09:04:08 +0200] "GET /.env.example HTTP/1.1" 403 541 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
lindi
2026-05-30 06:13:14
(4 days ago)
Probing for resource vulnerabilities
...
Web Spam
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
andypiper
2026-05-30 01:02:32
(5 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-30 00:49:04
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-05-30 00:11:29
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ช
sid3windr
2026-05-29 20:35:33
(5 days ago)
GET /.env (Tarpitted for , wasted 120B)
Web App Attack
๐บ๐ธ
LotPhantom
2026-05-29 20:02:43
(5 days ago)
2026/05/29 20:02:42 [error] 4014395#4014395: *105575 access forbidden by rule, client: 64.89.160.19, ...
show more
2026/05/29 20:02:42 [error] 4014395#4014395: *105575 access forbidden by rule, client: 64.89.160.19, server: wynnesmiles.com, request: "GET /.env HTTP/1.1", host: "www.wynnesmiles.com"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-29 19:09:49
(5 days ago)
64.89.160.19 - - [29/May/2026:22:01:04 +0300] "GET /.env HTTP/1.1" 404 3301 "-" "Mozilla/5.0 (Window ...
show more
64.89.160.19 - - [29/May/2026:22:01:04 +0300] "GET /.env HTTP/1.1" 404 3301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
64.89.160.19 - - [29/May/2026:22:09:47 +0300] "GET /.env HTTP/1.1" 404 3313 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ญ๐บ
szasa
2026-05-29 17:11:07
(5 days ago)
2026/05/29 19:11:05 [error] 2143328#2143328: *2827152 access forbidden by rule, client: 64.89.160.19 ...
show more
2026/05/29 19:11:05 [error] 2143328#2143328: *2827152 access forbidden by rule, client: 64.89.160.19, server: datamentor.hu, request: "GET /.env HTTP/1.1", host: "beszerzokozpont.hu"
2026/05/29 19:11:05 [error] 2143328#2143328: *2827166 access forbidden by rule, client: 64.89.160.19, server: datamentor.hu, request: "GET /.env HTTP/1.1", host: "www.datamentor.hu"
2026/05/29 19:11:05 [error] 2143330#2143330: *2827161 access forbidden by rule, client: 64.89.160.19, server: datamentor.hu, request: "GET /.env HTTP/1.1", host: "www.beszerzokozpont.hu"
2026/05/29 19:11:06 [error] 2143328#2143328: *2827158 access forbidden by rule, client: 64.89.160.19, server: datamentor.hu, request: "GET /.env HTTP/1.1", host: "datamentor.hu"
...
show less
Web App Attack
๐ซ๐ท
Thibault Millant
2026-05-29 16:53:44
(5 days ago)
64.89.160.19 - - [29/May/2026:18:53:43 +0200] "GET /config.js HTTP/1.1" 404 10098 "-" "Mozilla/5.0 ( ...
show more
64.89.160.19 - - [29/May/2026:18:53:43 +0200] "GET /config.js HTTP/1.1" 404 10098 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
64.89.160.19 - - [29/May/2026:18:53:43 +0200] "GET /js/config.js HTTP/1.1" 404 10098 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
...
show less
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-05-29 16:40:45
(5 days ago)
(caddyscan) Scanner path probe from 64.89.160.19 (LU/Luxembourg/-): 5 in the last 3600 secs; Ports: ...
show more
(caddyscan) Scanner path probe from 64.89.160.19 (LU/Luxembourg/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 64.89.160.19 - - [29/May/2026:16:27:53 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 64.89.160.19 - - [29/May/2026:16:27:53 +0000] "GET /.env.example HTTP/1.1"
[REDACTED] 200 2627 64.89.160.19 - - [29/May/2026:16:27:53 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 64.89.160.19 - - [29/May/2026:16:27:53 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 64.89.160.19 - - [29/May/2026:16:40:43 +0000] "GET /.env.production HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-29 16:33:30
(5 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฉ๐ช
FeG Deutschland
2026-05-29 12:09:32
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ซ๐ฎ
as211431.net
2026-05-29 11:40:27
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from LU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from LU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /config.js
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
gadix
2026-05-29 10:23:04
(5 days ago)
[29/May/2026:12:23:02.692436 +0200] ahlpBvt5GmBjbJuRZfjB-wAAAAk 64.89.160.19 40262 127.0.0.1 7081
[2 ...
show more
[29/May/2026:12:23:02.692436 +0200] ahlpBvt5GmBjbJuRZfjB-wAAAAk 64.89.160.19 40262 127.0.0.1 7081
[29/May/2026:12:23:02.701688 +0200] ahlpBqvV4l8bFL11K8l7UQAAAAw 64.89.160.19 40272 127.0.0.1 7081
[29/May/2026:12:23:02.753845 +0200] ahlpBhYZGxPH32rAMsvyWQAAAAA 64.89.160.19 40302 127.0.0.1 7081
...
show less
Web App Attack